Impact
This vulnerability is an XSS flaw in F‑RevoCRM. An attacker can inject malicious script into a page that a logged‑in user will view. The script runs in the context of the authenticated session and can potentially perform unintended operations such as manipulating data or executing functions within the application.
Affected Systems
F‑RevoCRM from Thinkingreed Inc. The affected version is not specified in the CVE data, so all installations of the product should be considered potentially vulnerable. The vendor is Thinkingreed Inc.’s F‑RevoCRM.
Risk and Exploitability
The CVSS score is 5.1, indicating moderate impact. The EPSS score is less than 1%, signaling a very low probability of exploitation at the time of analysis. The vulnerability is not listed in CISA KEV, so no current known attacks are documented. The likely attack vector requires a victim to view a crafted resource while logged in, implying the need for social engineering or a malicious link. An attacker would need the victim to be authenticated and to open the page containing the injected script.
OpenCVE Enrichment